WO2020233236A1 - 一种应用于区块链的可消耗凭证的验证方法和装置 - Google Patents
一种应用于区块链的可消耗凭证的验证方法和装置 Download PDFInfo
- Publication number
- WO2020233236A1 WO2020233236A1 PCT/CN2020/082204 CN2020082204W WO2020233236A1 WO 2020233236 A1 WO2020233236 A1 WO 2020233236A1 CN 2020082204 W CN2020082204 W CN 2020082204W WO 2020233236 A1 WO2020233236 A1 WO 2020233236A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- verification
- certificate
- party
- user
- record
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/64—Protecting data integrity, e.g. using checksums, certificates or signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3829—Payment protocols; Details thereof insuring higher security of transaction involving key management
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q40/00—Finance; Insurance; Tax strategies; Processing of corporate or income taxes
- G06Q40/04—Trading; Exchange, e.g. stocks, commodities, derivatives or currency exchange
Definitions
- the embodiments of the present invention relate to the field of Fintech, and in particular, to a method and device for verifying a consumable certificate applied to a blockchain (Blockchain).
- Blockchain is a way for all people to participate in bookkeeping, which has the characteristics of decentralization and trustlessness. The most important thing about blockchain is to solve the problem of intermediary credit. In the past, it was difficult for two people who did not know and trust each other to achieve collaboration, and it was necessary to rely on a third party. For example, payment behavior, any kind of transfer in the past, must have an institution such as a bank or Alipay. However, through blockchain technology, Bitcoin is the first time that human beings can complete mutual trust transfer behavior without any intermediary institutions. This is a major breakthrough in the blockchain, and the blockchain is becoming more and more important. Get people's attention.
- the present invention provides a method and device for verifying a consumable certificate applied to a blockchain to solve the problem of untrustworthy and low security of the verification request of the certificate in the prior art.
- the embodiment of the present invention provides a method for verifying a consumable certificate applied to a blockchain, including:
- the verifier obtains the certificate provided by the user for verification; the certificate records each valid verification record;
- the verification party obtains the verification registration of the certificate from the blockchain, and the verification registration records the first hash value; the first hash value is the last time the certificate was verified Generated based on all valid verification records;
- the verification party generates a second Hash value according to the effective verification records in the certificate
- the verification party determines that the certificate can be used for verification.
- the verification record further includes a verification signature for signing the first Hash value by the verification party last verification;
- determining that the voucher can be used for verification includes:
- the verification party obtains the verification record of the last verification from the certificate
- the verification party verifies the verification signature according to the verification institution information in the verification record of the previous verification;
- the verification party determines that the certificate can be used for verification.
- the method further includes:
- the verification returns a lock request for the certificate to the user;
- the lock request is used by the user to generate a lock signature and upload the lock signature to the blockchain;
- the lock signature is used to indicate
- the blockchain sets the lock state in the verification registration to a locked state and records the lock signature in the verification registration;
- the verification party receives a lock success response sent by the user; the lock success response is used to trigger the verification party to perform verification.
- the method further includes:
- the verification party sends the verification party record to the user
- the verification party obtains the user-side record returned by the user
- the verification party determines the verification record corresponding to the verification request according to the verification party record and the user record;
- the verification party generates a third Hash value according to each verification record in the voucher and the verification record corresponding to the verification request;
- the verification party updates the first Hash value in the verification registration of the certificate in the blockchain to the third Hash value.
- the method further includes:
- the verification party changes the writing status of the certificate to unlocked, and writes the locked signature to the blockchain;
- the verification returns a successful response to the user.
- the method before the verification party updates the first Hash value on the blockchain to the third Hash value, the method further includes:
- the verification party queries the writing status of the certificate on the blockchain
- the method before the verification party obtains the verification registration of the certificate from the blockchain, the method further includes:
- the verification party obtains the verification request of the certificate sent by the user;
- the verification request of the certificate includes the attribute signature of the certificate and the number of verifications;
- the verification party determines the remaining available times of the voucher according to the voucher
- the verification party verifies whether the verification times of the verification request is less than or equal to the remaining available times of the certificate; the verification party obtains the public key of the certificate issuer from the blockchain, and verifies the Whether the attribute signature of the certificate is legal.
- the method further includes:
- the verification value sends the verification value of the verification request of the certificate to the user; the verification value is used by the verification party to generate a verification record of the verification request and verify the verification value for the user The verification record generated by the verification party.
- the embodiment of the present invention provides a verification device for a consumable certificate applied to a blockchain, including:
- the transceiver unit is used to obtain the certificate provided by the user for verification; the certificate records each valid verification record; obtain the verification registration of the certificate from the blockchain, the verification registration A first hash value is recorded in, the first hash value is generated based on all valid verification records after the last verification of the voucher;
- the processing unit is configured to generate a second Hash value according to each valid verification record in the voucher; when it is confirmed that the first Hash value is consistent with the second Hash value, it is determined that the voucher can be used for verification pin.
- the verification record further includes a verification signature used by the verification party to sign the first Hash value in the last verification; the processing unit is configured to: Obtain the verification record of the last verification; verify the verification signature according to the verification institution information in the verification record of the last verification; verify the first Hash value and the second Hash When the values are consistent and the verification of the verification signature is passed, it is determined that the certificate can be used for verification.
- the transceiver unit is further configured to: return a lock request for the credential to the user; the lock request is used for the user to generate a lock signature and upload the lock signature to the user.
- the blockchain the lock signature is used to instruct the blockchain to set the lock state in the verification registration to the locked state and record the lock signature in the verification registration; receive the user's sending The lock successful response; the lock successful response is used to trigger the verification party to write off.
- the transceiver unit is further configured to: send the verification party record to the user; obtain the user-side record returned by the user;
- the processing unit is further configured to: after verifying that the lock signature is legal, generate a verification party record corresponding to the verification request; and determine the verification request corresponding to the verification request based on the verification party record and the user record The verification record; the verification record corresponding to the verification request and each valid verification record in the voucher generates a third Hash value; the verification of the voucher in the blockchain is updated The first Hash value in the registration is the third Hash value.
- the processing unit is further configured to: modify the writing status of the certificate to unlock, and write the lock signature to the blockchain; and return a successful verification response to the user .
- the processing unit is configured to: query the writing status of the voucher on the blockchain; if it is determined that the writing status is unlocked, return an instruction to relock to the user , And after deleting the second verification record in the voucher, return to the user.
- the transceiver unit is configured to: obtain a verification request for the voucher sent by the user; the verification request for the voucher includes the attribute signature of the voucher and the number of verifications;
- the processing unit is configured to verify whether the number of times of verification of the verification request is less than or equal to the available times of the certificate; the verification party obtains the public key of the certificate issuer from the blockchain, and verifies After the attribute signature of the certificate is legal, the verification result of the verification request of the certificate is returned.
- the processing unit is configured to: send the verification value of the verification request of the voucher to the user; the verification value is used by the verification party to generate the verification request And verify the verification record generated by the verification party for the user.
- An embodiment of the present invention provides a computer storage medium, where the computer-readable storage medium includes a computer program, and when the computer program runs on a computer, the computer executes the method described in any one of the foregoing embodiments.
- An embodiment of the present invention provides a computer program product containing instructions, which when the instructions run on a computer, cause the computer to execute the method described in any one of the foregoing embodiments.
- the embodiment of the present invention provides a computer device, including:
- At least one memory for storing program instructions
- At least one processor is configured to invoke program instructions stored in the memory, and execute the method according to any one of the foregoing embodiments according to the obtained program.
- the verification party compares the hash value in the verification registration on the blockchain with the hash value generated after the verification record in the certificate is serialized to verify whether the verification record of the expendable certificate has been tampered with Over. It only needs to be on the chain when it is written off, and no private data is exposed on the blockchain, which improves the efficiency of verification.
- Figure 1a is a schematic diagram of a system architecture provided by an embodiment of the present invention.
- Figure 1b is a schematic diagram of another system architecture provided by an embodiment of the present invention.
- FIG. 2 is a schematic flowchart of a method for expendable credentials provided by an embodiment of the present invention
- FIG. 3 is a schematic structural diagram of a consumable credential device provided by an embodiment of the present invention.
- Figure 4 is a schematic structural diagram of a computer device provided by an embodiment of the present invention.
- Verifier This role is used to describe the organization that has the authority to verify the certificate. Other institutions may apply for a verification certificate from the verification party.
- Issuer This role is used to describe an organization that has the authority to generate certificates and issue them to users.
- This role can obtain the certificate sent by the issuer, and can apply to the verifier for verification of the certificate.
- Blockchain All participants have the ability to read and write to the blockchain. Among them, the participants can be the verification party, issuer, and user who have a blockchain account.
- Block used to record data collections and status results divided according to certain conditions, which are formed after each node reaches a consensus.
- the data to be recorded is mainly data or user data
- blocks can be divided by time. For example, a block is generated every 10 seconds (s), then this block is to record all the data in these 10s, or a block is generated every day, then this The block is to record all the data during the day; or, the block can also be divided according to the number of received data or history update information, for example, after receiving a specified number of data or history update information, a Block, then this block is used to record the specified amount of data update information that has been received.
- a block includes a block header and a block body.
- the block header includes the previous block address (Prev-block)
- the previous block address can be stored in the block header in the form of the previous block hash code (pre-Hash)
- pre-Hash previous block hash code
- the direction of the address connects all the blocks in series to form a blockchain.
- the block body is used to store specific data, such as data in the embodiment of the present invention.
- Blockchain or distributed data recording ledger, is a chained data structure in which data storage blocks are sequentially connected in a certain order. The blocks are connected in sequence to form a blockchain.
- Node refers to the computing equipment that participates in the process of data recording or verification in the blockchain network.
- computers, mobile phones, mining machines, desktops, or servers that have computing capabilities can all be used as nodes in the blockchain network.
- any device in the network can be used as a node of the blockchain and can participate in the recording and storage of the blockchain. Based on the consensus mechanism between nodes, the entire block is jointly maintained through competitive computing. chain. Since any node can have a complete copy of the data of the blockchain, any node fails, and the remaining nodes can still work normally, so the reliability of the blockchain-based storage method is high.
- each node can have the same authority, so there is no centralized equipment or management organization. All data information in the blockchain is open and transparent, and the modification of its own data by a single node or even multiple nodes cannot affect the data of other nodes unless it can control more than half of the nodes in the entire blockchain network to modify. However, this method is too difficult, and each block in the blockchain is associated with two blocks before and after. If you want to tamper with the data of a block, you need to tamper with multiple blocks related to it. Data is more difficult, so the data stored based on the blockchain is immutable.
- Hash value An algorithm that generates a hash map value for a certain string, such as sha3.
- FIG. 1a exemplarily shows a schematic diagram of a system architecture to which an embodiment of the present invention is applicable.
- the system architecture to which an embodiment of the present invention is applicable includes a user 101, a verification party 102, an issuer 103, and a blockchain Network 104.
- the certificate issuer 103 is used to issue consumable certificates to users.
- Certificate holder user 101
- the credential verification party can be a role such as a merchant. This role can verify the credentials provided by the user and provide services to the user.
- User 101 sends a certificate verification request to the verification party; the verification party is connected to the blockchain network and sends the data that needs to be chained to the blockchain network; the user is connected to the blockchain network to verify the response returned by the verification party data.
- the nodes in the blockchain network can be accounting nodes or ordinary nodes.
- Each participating institution such as the verification party, issuer, and user, uses the agreed asymmetric encryption algorithm, such as ECDSA to generate its own public-private key pair; store the private key in its own private database, and then upload the public key to the chain.
- ECDSA agreed asymmetric encryption algorithm
- institution A publishes its public key A to the blockchain
- institution B publishes its public key B to the blockchain.
- the consumable certificate needs to be abstracted into a certificate Token on the blockchain, and then the entire life cycle of the issuance of the certificate and the verification of the certificate are on the chain.
- this approach is very inefficient: merchants may send millions of coupons every day, and their full tokenization will put a huge burden on the blockchain.
- embodiments of the present invention provide a consumable credential method applied to a blockchain, including:
- Step 1 The certificate issuer generates a certificate for the user and sends the certificate to the user.
- the check value may be a character string of variable length.
- the format of a consumable voucher can be represented by a json string, and its attribute items can include the following fields, as shown in Table 1:
- the business data determined by the issuer itself can be "full 50-25", “-yuan movie", "prescription” and other data, which are not limited here.
- the signature generated by the issuer may be the original text generated by the issuer based on the attribute information in the certificate, for example, it may be the original text based on other content that does not include the verification record.
- the issuer can use its private key to serialize all the attribute items of the certificate to generate a signature.
- the verification agency or user can verify the signature value through the public key published by the issuer on the blockchain.
- the recipient can be the user, that is, after the issuer has generated the voucher, the voucher is sent to the user, or it can be sent to the user through a third party, which is not limited here.
- the write-off record set can be another json string nested in the json of the expendable certificate, which is empty when the certificate is created.
- the verification record set may include multiple verification records.
- the format of each verification record can be serialized, that is, the content of a table is converted into a series according to the content of a table. String format. As shown in Table 2, it includes the following fields:
- each verification record needs to be signed by the user and the verification agency. This is to ensure that both parties use digital signatures to confirm the legal use of the certificate.
- the verification user signature may be a signature generated by the user based on the verification record as the original text
- the verification agency signature may be a signature generated by the verification agency using the verification record as the original text.
- the user signature that can be verified may be a signature generated by the user based on his own private key, the verification time, the verification organization, the remaining times, and the verification value of the original text.
- the check value is used by the verification party to generate a verification record of the verification request and verify the verification record generated by the verification party for the user.
- the check value can be a string of unspecified length, which is used as one of the input parameters of the digital signature algorithm.
- the verification value needs to be provided at the same time. This provides the digital signature with the ability to resist replay attacks, so that the signature can be correctly verified only when the verification value is exchanged between the designated user and the verification party.
- Step 2 The user sends a verification request of the voucher to the verification party.
- the verification request of the voucher includes the voucher and the number of verifications.
- the verification party verifies whether the number of verifications of the verification request is less than or equal to the remaining available times of the voucher according to the certificate; The number of cancellations and the maximum available number of times in the certificate and the last written verification record, confirm the remaining available times of the certificate, and determine that the verifier obtains the public key of the certificate issuer from the blockchain To verify whether the attribute signature of the certificate is legal.
- an embodiment of the present invention provides a method for verifying a consumable certificate applied to a blockchain, including:
- Step 201 The verifier obtains the certificate provided by the user for verification; the certificate records each valid verification record;
- Step 202 The verification party obtains the verification registration of the certificate from the blockchain, and the verification registration records the first hash value; the first hash value is the last verification of the certificate Later generated based on all valid verification records;
- the verification record of each certificate needs to be stored on the chain.
- the verification and cancellation registration of the certificate can be established for each certificate. In the specific implementation process, it can be stored through a serialized field. As shown in Table 3, the verification and registration of the voucher includes the first Hash value.
- Hash The Hash value of the serialized string of the verification record of the certificate Hash signature of verification record The signature generated by the last verification party of the certificate
- the verification record further includes a verification signature for the verification party that was previously verified to sign the first Hash value.
- the verification signature may be a signature generated based on the Hash value and the verification value of the verification record generated by the last-level verification party.
- Step 203 The verification party generates a second Hash value according to the effective verification records in the certificate
- Step 204 When confirming that the first Hash value is consistent with the second Hash value, the verification party determines that the certificate can be used for verification.
- the certificate only needs to be chained when the certificate is verified, and only the latest state of the certificate, the hash value and the signature of the verification record are stored on the chain, which effectively guarantees the efficiency and safety of certificate verification.
- the verification party verifies whether the verification record of the certificate has been tampered with.
- One possible implementation method includes:
- the verification party obtains the verification record of the last verification from the certificate
- the verification party verifies the verification signature according to the verification institution information in the verification record of the previous verification;
- the verification party determines that the certificate can be used for verification.
- the verification party will compare the Hash in the verification registration on the chain with the hash value generated after the verification record of the certificate is serialized. If the verification record is not empty and the first Hash value is consistent with the second Hash value, then further, obtain the public key of the last verification party from the chain, and use the first Hash value as the original text to verify whether the verification signature is legitimate. If either of the two is illegal, return failure.
- the verification party can verify the content of the certificate and the legality of the signature.
- a possible implementation is to obtain the issuer's public key from the chain according to the address of the certificate issuer, and then use all the attributes of the certificate and the serialized string as the original text to verify whether the signature is legal. If it is not legal, return failure.
- the verification party enters according to whether the verification record set in the provided certificate is empty:
- the set of verification records is not empty, for each verification record in the certificate, obtain the verification agency public key and the user public key from the blockchain, and then verify whether the verification agency signature and verification user signature are legal . If any signature in any one of the verification records is illegal, return failure. Otherwise, go to the next step.
- the set of verification records is empty, it is determined that the certificate has not been verified, and there is no verification registration of the certificate on the blockchain. At this time, add a record of the verification and registration of the certificate in the verification and verification on the chain and fill in the ID of the certificate or the ID of the verification and registration generated for the certificate.
- a smart contract can be used to perform transactional locks on verification to ensure that neither the holder of the certificate nor the verification party is likely to conduct a double-spending attack.
- a possible implementation method after the verification party determines that the certificate can be used for verification, further includes:
- the verification returns a lock request for the certificate to the user;
- the lock request is used by the user to generate a lock signature and upload the lock signature to the blockchain;
- the lock signature is used to indicate
- the blockchain sets the lock state in the verification registration to a locked state and records the lock signature in the verification registration;
- the verification value of the verification request of the credential may be sent to the user while sending the lock request; the verification value may be used by the user according to the verification The value generates a lock signature to uniquely identify this verification, so that the verification party can trigger the verification process after obtaining the lock success response sent by the user.
- the verification party receives a lock success response sent by the user; the lock success response is used to trigger the verification party to perform verification.
- the user uses the Hash and check value in the verification and registration as the original text, and generates the lock signature with his own private key.
- the user modifies the corresponding entry of the certificate in the verification registration, sets the lock status to Y, and attaches the lock signature.
- the lock status and the lock signature can be stored in the verification registration of the certificate.
- serialized fields can be used for storage, as shown in Table 4:
- Hash The Hash value of the serialized string of the verification record of the certificate
- Hash signature of verification record The signature generated by the last verification party of the certificate Locked state Y/N Lock signature User-generated signature
- the verification party is in the blockchain to check whether the certificate is being registered in a locked state. If the credential is currently locked, it will also return a failure.
- a possible implementation can include:
- Step 1 After the verification party verifies that the lock signature is legal, a record of the verification party corresponding to the verification request is generated;
- the user informs the verification party that the lock process has been completed and the verification can be started; the verification party finds the attribute item of the corresponding voucher ID from the voucher status table and the verification value generated corresponding to the verification request , Obtain the user's public key from the chain, check whether the certificate has been correctly locked, and whether the signature is legal. If it is not locked or the signature is invalid, it returns a failure.
- the verifier generates a record of the verifier based on the verification record set of the certificate.
- the record of the verifier includes the remaining number of times, the address of the verification institution, the verification time, and the verification value.
- the verifier can also write the signature of the verification agency in the verifier record. Specifically, the verification time, the address of the verification agency, the remaining number of times, and the verification value can be used as the original text together with its own private key. Generate a signature and fill it in the "Signature of Verification Agency" item recorded by the verification party.
- Step 2 The verification party sends the record of the verification party to the user;
- the verification party sends the verification record to the user, asking the user to confirm the implementation of the verification party record and sign.
- Step 3 The verification party obtains the user record returned by the user
- the user obtains the public key of the verification agency from the chain to verify whether the verification agency signature is legal. If it is illegal or if there is an error in the verification content, the verification agency is required to regenerate the verification party record. Otherwise, the user approves the signature of the verification agency and generates a signature with its own private key, and fills it in the "Verification of User Signature" item in the verification record.
- the original text of the signature can be the same original text as the signature of the verification agency, or a different original text, which is not limited here.
- Step 4 The verification party determines the verification record corresponding to the verification request according to the verification party record and the user side record;
- the verification party obtains the user's public key from the chain, verifies whether the verification user's signature is legal, and fails if it is not. Otherwise, it means that a complete write-off record has been generated.
- the verification party updates the verification record set of the certificate, adds a verification record, and fills in the verification party record and the user record.
- the update of the set of write-off records can also be updated at the second step, and the reviewer does not need to separately generate the record of the write-off party, and only needs to verify and send the updated certificate to the user.
- Step 5 The verification party generates a third Hash value according to the verification records of each verification in the certificate and the verification records corresponding to the verification request;
- Step 6 The verification party updates the first Hash value in the verification registration of the certificate in the blockchain to the third Hash value.
- the verification party serializes all verification records to generate a Hash, and then writes the Hash into the “value of the entry” of the entry corresponding to the certificate ID in the verification registration on the chain.
- the Hash value as the original text, use your own private key to generate a signature, and write it into the "Into the verification signature item" of the verification registration corresponding entry.
- the method further includes:
- the verification party modifies the writing status of the certificate to unlock, and writes the lock signature into the blockchain; the verification party returns a successful verification response to the user.
- the verification party can modify the locked status in the verification registration to N and delete the locked signature.
- the lock state can also be modified by the user in this step, which is not limited here.
- the verification response to the user that the verification is successful may also include providing the user with a business service corresponding to the credential.
- the method before the verification party updates the first Hash value on the blockchain to the third Hash value, the method further includes:
- the verification party queries the writing status of the certificate on the blockchain
- the verification party finds that the lock status is no longer Y, it means that the user may be trying to double-spend the credential.
- the verification party can immediately terminate the verification process and request the user to enter the credential lock process again.
- the verification party can also use the blockchain with permissions to ensure that the unlocked state can only be modified by the verification party, further avoiding the possibility of double spending and improving the security of verification.
- all certificates need to be chained when they are verified, and only the latest state of the certificate, the Hash and signature of the verification record are stored on the chain; even if a certificate is used multiple times, only one chain is required Record; the entire verification process only requires a maximum of four blockchain write operations.
- the verification process can effectively prevent double-spending attacks by either the user or the verification party, effectively ensuring the efficiency and security of credential verification.
- an embodiment of the present invention provides a verification device for a consumable certificate applied to a blockchain, including:
- the transceiving unit 301 is used to obtain a certificate provided by the user for verification; the certificate records each valid verification record; obtains the verification registration of the certificate from the blockchain, and the verification A first hash value is recorded in the registration; the first hash value is generated based on all valid verification records after the last verification of the voucher;
- the processing unit 302 is configured to generate a second Hash value according to each valid verification record in the voucher; when it is confirmed that the first Hash value is consistent with the second Hash value, it is determined that the voucher can be used Write off.
- the verification record further includes a verification signature for the verification party that was previously verified to sign the first Hash value;
- the processing unit 302 is configured to: Obtain the verification record of the last verification; verify the verification signature according to the verification institution information in the verification record of the previous verification; confirm the first Hash value and the second When the Hash value is consistent and the verification of the verification signature is passed, it is determined that the certificate can be used for verification.
- the transceiver unit 301 is further configured to: return a lock request for the credential to the user; the lock request is used for the user to generate a lock signature and upload the lock signature to The blockchain; the lock signature is used to instruct the blockchain to set the lock state in the verification registration to the locked state and record the lock signature in the verification registration; receive the user The sent lock success response; the lock success response is used to trigger the verification party to perform verification.
- the transceiver unit is further configured to: send the verification party record to the user; obtain the user-side record returned by the user;
- the processing unit is further configured to: after verifying that the lock signature is legal, generate a verification party record corresponding to the verification request; and determine the verification request corresponding to the verification request based on the verification party record and the user record The verification record; the verification record corresponding to the verification request and each valid verification record in the voucher generates a third Hash value; the verification of the voucher in the blockchain is updated The first Hash value in the registration is the third Hash value.
- the processing unit is further configured to: modify the writing status of the certificate to unlock, and write the lock signature to the blockchain; and return a successful verification response to the user .
- the processing unit is configured to: query the writing status of the voucher on the blockchain; if it is determined that the writing status is unlocked, return an instruction to relock to the user , And after deleting the second verification record in the voucher, return to the user.
- the transceiver unit is configured to: obtain a verification request for the voucher sent by the user; the verification request for the voucher includes the attribute signature of the voucher and the number of verifications;
- the processing unit is configured to verify whether the number of times of verification of the verification request is less than or equal to the available times of the certificate; the verification party obtains the public key of the certificate issuer from the blockchain, and verifies After the attribute signature of the certificate is legal, the verification result of the verification request of the certificate is returned.
- the processing unit is configured to: if it is determined that the verification result is passed, send a check value of the verification request of the voucher to the user; the check value is used for all
- the verification party generates a verification record of the verification request and verifies the verification record generated by the verification party for the user.
- an embodiment of the present invention also provides a computer device for executing a method of a user or a verification party in any embodiment of the present invention, and may include a memory 1001 and a processor 1002.
- the memory 1001 is used to store a computer program executed by the processor 1002.
- the memory 1001 may mainly include a program storage area and a data storage area.
- the program storage area may store an operating system, an application program required for at least one function, and the like; the data storage area may store data created according to the use of a computer device.
- the processor 1002 may be a central processing unit (central processing unit, CPU), or a digital processing unit or the like.
- the embodiment of the present invention does not limit the specific connection medium between the foregoing memory 1001 and the processor 1002.
- the memory 1001 and the processor 1002 are connected through a bus 1003, and the bus 1003 is represented by a thick line in FIG. 4.
- the connection mode between other components is only for schematic illustration, not Limited.
- the bus 1003 can be divided into an address bus, a data bus, a control bus, and the like. For ease of presentation, only one thick line is used to represent in FIG. 4, but it does not mean that there is only one bus or one type of bus.
- the memory 1001 may be a volatile memory (volatile memory), such as a random-access memory (random-access memory, RAM); the memory 1001 may also be a non-volatile memory (non-volatile memory), such as a read-only memory, flash memory Flash memory, hard disk drive (HDD) or solid-state drive (SSD), or memory 1001 can be used to carry or store desired program codes in the form of instructions or data structures and can be used by Any other medium accessed by the computer, but not limited to this.
- the memory 1001 may be a combination of the above-mentioned memories.
- the processor 1002 is configured to execute the block chain-based consumable voucher method provided by the embodiment of the present invention when calling the computer program stored in the memory 1001.
- An embodiment of the present invention also provides a computer storage medium that stores computer executable instructions required to execute the foregoing processor, and contains a program used to execute the foregoing processor.
- all aspects of the blockchain-based consumable credential method provided by the present invention can also be implemented in the form of a program product, which includes program code, when the program product runs on a computer device At the time, the program code is used to make the computer device execute the steps in the block chain-based consumable voucher method provided according to various exemplary implementations of the present invention described above in this specification.
- the computer device can execute The embodiment of the present invention provides a method for verifying a consumable certificate based on a blockchain.
- the program product can use any combination of one or more readable media.
- the readable medium may be a readable signal medium or a readable storage medium.
- the readable storage medium may be, for example, but not limited to, an electric, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: electrical connections with one or more wires, portable disks, hard disks, random access memory (RAM), read only memory (ROM), erasable Type programmable read only memory (EPROM or flash memory), optical fiber, portable compact disk read only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination of the above.
- the program product based on the block chain-based consumable credential method provided in the embodiment of the present invention can adopt a portable compact disk read-only memory (CD-ROM) and include program code, and can run on a computing device.
- CD-ROM portable compact disk read-only memory
- the program product of the present invention is not limited thereto.
- the readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, device, or device.
- the readable signal medium may include a data signal propagated in baseband or as a part of a carrier wave, and readable program code is carried therein. This propagated data signal can take many forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination of the foregoing.
- the readable signal medium may also be any readable medium other than a readable storage medium, and the readable medium may send, propagate, or transmit a program for use by or in combination with the instruction execution system, apparatus, or device.
- the program code contained on the readable medium can be transmitted by any suitable medium, including, but not limited to, wireless, wired, optical cable, RF, etc., or any suitable combination of the above.
- the program code used to perform the operations of the present invention can be written in any combination of one or more programming languages.
- the programming languages include object-oriented programming languages—such as Java, C++, etc., as well as conventional procedural styles. Programming language-such as "C" language or similar programming language.
- the program code can be executed entirely on the user's computing device, partly on the user's device, executed as an independent software package, partly on the user's computing device and partly executed on the remote computing device, or entirely on the remote computing device or server Executed on.
- the remote computing device can be connected to the user's computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (for example, using Internet services) Provider to connect via the Internet).
- LAN local area network
- WAN wide area network
- an external computing device for example, using Internet services
- the embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
- a computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
- These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing equipment to work in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including the instruction device.
- the device implements the functions specified in one process or multiple processes in the flowchart and/or one block or multiple blocks in the block diagram.
- These computer program instructions can also be loaded on a computer or other programmable data processing equipment, so that a series of operation steps are executed on the computer or other programmable equipment to produce computer-implemented processing, so as to execute on the computer or other programmable equipment.
- the instructions provide steps for implementing functions specified in a flow or multiple flows in the flowchart and/or a block or multiple blocks in the block diagram.
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Theoretical Computer Science (AREA)
- Finance (AREA)
- Computer Security & Cryptography (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Economics (AREA)
- Technology Law (AREA)
- Marketing (AREA)
- Development Economics (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Storage Device Security (AREA)
Abstract
Description
| Key | Value |
| 发行方 | 发行方链上地址 |
| 发行时间及有效期 | 发行时间及有效期 |
| ID | UUID字符串 |
| 接收方 | 接收方链上地址 |
| 内容 | 发行方自行确定的业务数据 |
| 最大可用次数 | 凭证的最大可使用次数 |
| 签名 | 发行方生成的签名 |
| 核销记录集 | 多条凭证核销记录的集合,创建时刻为空 |
| Key | Value |
| 核销时间 | 核销时间 |
| 核销机构 | 核销机构链上地址 |
| 剩余使用次数 | 本次所核销后的剩余使用次数 |
| 校验值 | 核销随机值 |
| 核销用户签名 | 用户生成的签名 |
| 核销机构签名 | 核销机构生成的签名 |
| Key | Value |
| ID | UUID字符串,与凭证ID相同 |
| 核销记录Hash | 该凭证的核销记录序列化字符串的Hash值 |
| 核销记录Hash签名 | 该凭证最后一次核销方生成的签名 |
| Key | Value |
| ID | UUID字符串 |
| 核销记录Hash | 该凭证的核销记录序列化字符串的Hash值 |
| 核销记录Hash签名 | 该凭证最后一次核销方生成的签名 |
| 锁定状态 | Y/N |
| 锁定签名 | 用户生成的签名 |
Claims (12)
- 一种应用于区块链的可消耗凭证的验证方法,其特征在于,包括:核销方获取用户提供的用以核销的凭证;所述凭证中记录有已生效的各次核销记录;所述核销方从区块链上获取所述凭证的核销登记,所述核销登记中记录有第一哈希Hash值;所述第一Hash值是所述凭证在上一次核销后根据所有已生效的核销记录生成的;所述核销方根据所述凭证中的已生效的各次核销记录生成第二Hash值;所述核销方在确认所述第一Hash值和所述第二Hash值一致时,确定所述凭证可用于核销。
- 如权利要求1所述的方法,其特征在于,所述核销记录中还包括上一次核销的核销方对所述第一Hash值进行签名的核销签名;所述核销方在确认所述第一Hash值和所述第二Hash值一致时,确定所述凭证可用于核销,包括:所述核销方从所述凭证中获取上一次核销的核销记录;所述核销方根据所述上一次核销的核销记录中的核销机构信息对所述核销签名进行验证;所述核销方在确认所述第一Hash值和所述第二Hash值一致且所述核销签名验证通过时,确定所述凭证可用于核销。
- 如权利要求1所述的方法,其特征在于,所述核销方确定所述凭证可用于核销之后,还包括:所述核销方向所述用户返回针对所述凭证的锁定请求;所述锁定请求用于所述用户生成锁定签名并将所述锁定签名上传至所述区块链;所述锁定签名用于指示所述区块链将所述核销登记中的锁定状态设置为锁定态并在所述核销登记中记录所述锁定签名;所述核销方接收所述用户发送的锁定成功响应;所述锁定成功响应用于 触发所述核销方进行核销。
- 如权利要求1所述的方法,其特征在于,所述核销方接收所述用户发送的锁定成功响应后,还包括:所述核销方验证所述锁定签名合法后,生成所述核销请求对应的核销方记录;所述核销方将所述核销方记录发送至所述用户;所述核销方获取所述用户返回的用户方记录;所述核销方根据所述核销方记录和所述用户方记录确定所述核销请求对应的核销记录;所述核销方根据所述凭证中的已生效的各次核销记录和所述核销请求对应的核销记录,生成第三Hash值;所述核销方更新所述区块链中所述凭证的核销登记中的第一Hash值为所述第三Hash值。
- 如权利要求4所述的方法,其特征在于,所述方法还包括:所述核销方将所述凭证的写入状态修改为解锁,并将所述锁定签名写入区块链;所述核销方向所述用户返回核销成功的响应。
- 如权利要求4所述的方法,其特征在于,所述核销方将区块链上的所述第一Hash值,更新为所述第三Hash值之前,还包括:所述核销方查询所述区块链上所述凭证的写入状态;若确定所述写入状态为解锁,则向所述用户返回重新锁定的指令,并将所述凭证中的所述第二核销记录删除后,返回至所述用户。
- 如权利要求1所述的方法,其特征在于,所述核销方从区块链上获取所述凭证的核销登记之前,还包括:所述核销方获取所述用户发送所述凭证的核销请求;所述凭证的核销请求包括所述凭证的属性签名及核销次数;所述核销方根据所述凭证,确定所述凭证的剩余可用次数;所述核销方验证所述核销请求的核销次数是否小于或等于所述凭证的剩余可用次数;所述核销方从区块链获取所述凭证的发行方的公钥,验证所述凭证的属性签名是否合法。
- 如权利要求7所述的方法,其特征在于,所述方法还包括:所述核销方向所述用户发送所述凭证的核销请求的校验值;所述校验值用于所述核销方生成所述核销请求的核销记录并为所述用户验证所述核销方生成的所述核销记录。
- 一种应用于区块链的可消耗凭证的验证装置,其特征在于,包括:收发单元,用于获取用户提供的用以核销的凭证;所述凭证中记录有已生效的各次核销记录;从区块链上获取所述凭证的核销登记,所述核销登记中记录有第一哈希Hash值;所述第一Hash值是所述凭证在上一次核销后根据所有已生效的核销记录生成的;处理单元,用于根据所述凭证中的已生效的各次核销记录生成第二Hash值;在确认所述第一Hash值和所述第二Hash值一致时,确定所述凭证可用于核销。
- 一种计算机存储介质,其特征在于,所述计算机可读存储介质包括计算机程序,当计算机程序在计算机上运行时,使得所述计算机执行如权利要求1至8任一所述的方法。
- 一种包含指令的计算机程序产品,其特征在于,当所述指令在计算机上运行时,使得所述计算机执行如权利要求1至8任一所述的方法。
- 一种计算机设备,其特征在于,包括:至少一个存储器,用于存储程序指令;至少一个处理器,用于调用所述存储器中存储的程序指令,按照获得的程序执行权利要求1至8任一项所述的方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201910427763.7 | 2019-05-22 | ||
| CN201910427763.7A CN110188572B (zh) | 2019-05-22 | 2019-05-22 | 一种应用于区块链的可消耗凭证的验证方法和装置 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020233236A1 true WO2020233236A1 (zh) | 2020-11-26 |
Family
ID=67717200
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2020/082204 Ceased WO2020233236A1 (zh) | 2019-05-22 | 2020-03-30 | 一种应用于区块链的可消耗凭证的验证方法和装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN110188572B (zh) |
| WO (1) | WO2020233236A1 (zh) |
Cited By (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114826653A (zh) * | 2022-03-10 | 2022-07-29 | 蚂蚁区块链科技(上海)有限公司 | 一种基于区块链网络的凭证验证方法、系统及装置 |
| US20250053974A1 (en) * | 2023-08-08 | 2025-02-13 | AVAST Software s.r.o. | Systems and methods for credential-based transactions over a network incorporating transaction codes |
| US12438730B2 (en) | 2022-11-04 | 2025-10-07 | AVAST Software s.r.o. | Systems and methods for reputation-based transactions over a network |
| US12483422B2 (en) | 2022-12-14 | 2025-11-25 | AVAST Software s.r.o. | Systems and methods for credential-based transactions over a network |
| US12524759B2 (en) | 2022-07-25 | 2026-01-13 | AVAST Software s.r.o. | Systems and methods for transacting over a network |
| US12541758B2 (en) | 2022-12-08 | 2026-02-03 | AVAST Software s.r.o. | Systems and methods for transacting over a network |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110188572B (zh) * | 2019-05-22 | 2024-09-20 | 深圳前海微众银行股份有限公司 | 一种应用于区块链的可消耗凭证的验证方法和装置 |
| CN111522829B (zh) * | 2020-04-14 | 2023-11-28 | 深圳市启迪网络科技有限公司 | 一种区块链上分布式锁实现方法 |
| CN111985918A (zh) * | 2020-07-27 | 2020-11-24 | 王李琰 | 基于区块链的电子凭证流通管理方法、系统及区块链平台 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20170085562A1 (en) * | 2015-09-18 | 2017-03-23 | Case Wallet, Inc. | Biometric data hashing, verification and security |
| US20180227293A1 (en) * | 2015-08-03 | 2018-08-09 | Coinplug Inc. | Certificate issuing system based on block chain |
| CN109146583A (zh) * | 2018-07-24 | 2019-01-04 | 腾讯科技(深圳)有限公司 | 票据处理方法和装置、存储介质及电子装置 |
| CN109559164A (zh) * | 2018-11-19 | 2019-04-02 | 泰康保险集团股份有限公司 | 优惠信息处理方法、装置、电子设备及计算机可读介质 |
| CN110188572A (zh) * | 2019-05-22 | 2019-08-30 | 深圳前海微众银行股份有限公司 | 一种应用于区块链的可消耗凭证的验证方法和装置 |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016179334A1 (en) * | 2015-05-05 | 2016-11-10 | ShoCard, Inc. | Identity management service using a block chain |
| US10735197B2 (en) * | 2016-07-29 | 2020-08-04 | Workday, Inc. | Blockchain-based secure credential and token management across multiple devices |
| TWI608434B (zh) * | 2016-12-20 | 2017-12-11 | Chunghwa Telecom Co Ltd | Decentralized electronic transaction record method and system with traceability verification mechanism |
| US11132704B2 (en) * | 2017-07-06 | 2021-09-28 | Mastercard International Incorporated | Method and system for electronic vouchers via blockchain |
| CN108389080B (zh) * | 2018-02-13 | 2021-08-24 | 口碑(上海)信息技术有限公司 | 交易处理方法及平台 |
| CN109447601B (zh) * | 2018-10-11 | 2022-04-12 | 上海保险交易所股份有限公司 | 在区块链网络中执行见证人转移交易的方法 |
| CN109660352B (zh) * | 2018-11-16 | 2021-12-03 | 深圳变设龙信息科技有限公司 | 一种基于区块链的分销关系记录方法、装置及终端设备 |
| CN109472651A (zh) * | 2018-11-21 | 2019-03-15 | 深圳前海微众银行股份有限公司 | 基于礼品卡的支付方法、设备及计算机可读存储介质 |
| CN109767245A (zh) * | 2019-01-08 | 2019-05-17 | 中国联合网络通信集团有限公司 | 消费信息核对方法、设备及存储介质 |
-
2019
- 2019-05-22 CN CN201910427763.7A patent/CN110188572B/zh active Active
-
2020
- 2020-03-30 WO PCT/CN2020/082204 patent/WO2020233236A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20180227293A1 (en) * | 2015-08-03 | 2018-08-09 | Coinplug Inc. | Certificate issuing system based on block chain |
| US20170085562A1 (en) * | 2015-09-18 | 2017-03-23 | Case Wallet, Inc. | Biometric data hashing, verification and security |
| CN109146583A (zh) * | 2018-07-24 | 2019-01-04 | 腾讯科技(深圳)有限公司 | 票据处理方法和装置、存储介质及电子装置 |
| CN109559164A (zh) * | 2018-11-19 | 2019-04-02 | 泰康保险集团股份有限公司 | 优惠信息处理方法、装置、电子设备及计算机可读介质 |
| CN110188572A (zh) * | 2019-05-22 | 2019-08-30 | 深圳前海微众银行股份有限公司 | 一种应用于区块链的可消耗凭证的验证方法和装置 |
Cited By (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114826653A (zh) * | 2022-03-10 | 2022-07-29 | 蚂蚁区块链科技(上海)有限公司 | 一种基于区块链网络的凭证验证方法、系统及装置 |
| US12524759B2 (en) | 2022-07-25 | 2026-01-13 | AVAST Software s.r.o. | Systems and methods for transacting over a network |
| US12438730B2 (en) | 2022-11-04 | 2025-10-07 | AVAST Software s.r.o. | Systems and methods for reputation-based transactions over a network |
| US12541758B2 (en) | 2022-12-08 | 2026-02-03 | AVAST Software s.r.o. | Systems and methods for transacting over a network |
| US12483422B2 (en) | 2022-12-14 | 2025-11-25 | AVAST Software s.r.o. | Systems and methods for credential-based transactions over a network |
| US20250053974A1 (en) * | 2023-08-08 | 2025-02-13 | AVAST Software s.r.o. | Systems and methods for credential-based transactions over a network incorporating transaction codes |
| US12524763B2 (en) * | 2023-08-08 | 2026-01-13 | AVAST Software s.r.o. | Systems and methods for credential-based transactions over a network incorporating transaction codes |
Also Published As
| Publication number | Publication date |
|---|---|
| CN110188572A (zh) | 2019-08-30 |
| CN110188572B (zh) | 2024-09-20 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2020233236A1 (zh) | 一种应用于区块链的可消耗凭证的验证方法和装置 | |
| US20240144280A1 (en) | Blockchain architecture with record security | |
| US10977632B2 (en) | Electronic bill management method, apparatus, and storage medium | |
| US11790370B2 (en) | Techniques for expediting processing of blockchain transactions | |
| TWI729719B (zh) | 基於區塊鏈的資料授權方法及裝置、電子設備及電腦可讀儲存媒介 | |
| US12126721B2 (en) | Reputation profile propagation on blockchain networks | |
| JP7791094B2 (ja) | プラットフォームサービスの検証 | |
| CN110089069B (zh) | 用于信息保护的系统和方法 | |
| CN108833081B (zh) | 一种基于区块链的设备组网认证方法 | |
| US11164165B1 (en) | Multi-asset blockchain network platform | |
| CN107924389B (zh) | 对分布式交易数据库的安全溯源的系统和方法 | |
| WO2021017441A1 (zh) | 基于区块链的数据授权方法及装置 | |
| JP7688652B2 (ja) | ブロックチェーンに関連するイベントのシーケンスに関するイベントストリーム | |
| JP2019500799A (ja) | 許可アクセスのためのクライアント装置、サーバー装置及びアクセス制御システム | |
| CN107306183A (zh) | 客户端、服务端、方法和身份验证系统 | |
| CN116210200A (zh) | 区块链通证 | |
| WO2020037927A1 (zh) | 可协商的区块链交易方法、装置、设备及存储介质 | |
| CN115119531A (zh) | 使用区块链事务的多因素认证 | |
| US12549376B2 (en) | Compressible blockchains | |
| KR20240011890A (ko) | 블록체인에서 생성된 데이터를 인증하는 방법 및 시스템 | |
| JP7730825B2 (ja) | イベントストリームの同期化 | |
| US20240320636A1 (en) | Cheques in blockchain networks | |
| US20240320662A1 (en) | Method for registering of token, a token reference register, secure transaction unit, and electronic payment transaction system | |
| US20220058597A1 (en) | Multi-asset blockchain network platform | |
| CN116707977A (zh) | 分布式系统的密钥管理方法、装置和计算机设备 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20808689 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20808689 Country of ref document: EP Kind code of ref document: A1 |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 16.03.2022) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20808689 Country of ref document: EP Kind code of ref document: A1 |